Re: Bug#962407: libhttp-tiny-perl: CVE-2023-31486: Does not default to verify SSL certificates

gregor herrmann <[email protected]>
Newsgroups gmane.linux.debian.devel.perl
Message-ID <[email protected]>
Control: tag -1 + fixed-upstream

On Thu, 26 May 2022 12:28:16 +0000, Damyan Ivanov wrote:

> > > https://github.com/chansen/p5-http-tiny/issues/134
> > Revisiting this issue now, the state seems to be:
> > The upstream ticket was closed with
> > "On reflection, we shouldn't make this change for backwards compatibility."

Update: This is now changed in HTTP::Tiny 0.083 (which also got
imported into perl core 5.38-RC1):
https://metacpan.org/release/DAGOLDEN/HTTP-Tiny-0.084/source/Changes#L11-12


Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmSQj/RfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgYf9g//Vo3fjIXARDCA/eYxmhv9EspSH+ylIf2PUXAGJC7uhLWHXlhLp6tgRZBa
QR+r5UtxND/CGzQ816I9KGsuZoBvzarOwXJUzwRRcbmSp9h74JzWPL+ng+cJgl60
JVWDOI9oM48W5hmGzyF+4HI+a2PkSaJoBZgodhbKUZpTqyNg6orAixqyJ/IYwfmw
0P119AEQ0WYKBaaTjoh9Ap1vyMqi1ulbps1ykD+Yd6bZ2E0eP9SpboUKvZFkpxA+
o5RM2inL/4sRCwkVJire+TxyXqmfhYxp60CFnASDyMTD4zAEBhKJpwP7KWSuQdh8
mpUGeuoUzbnp1fVIm9ZRcPRvv+u25kwttdyufxSlpSpjxdMZ08sL2ShS8DEewx12
3mqpVHrgovmJDoA6A6oaYlTJDL26gXf+O/LZqqzAUgjR5W3yazHB0vZ8MO6AsqiW
0/ZS/1vVJUhsOS2hmhXz7SUxYbPA3qhtPVsV353vWtrQbck4eMFEwfHmIBQCJ5SE
dYHtRjGwPmiutN6VQ6ppXgGRsjUqKqjzevJH3CIAinrQwbo0Qer7oe9noEk4Up0K
JmHSXMZpFbshJ0MwVAy0jsr1Q/N1rskMWpE9qz6E9ECBqNQkFlKV8BWKpUzKVZdm
s+1QH2F3ufA4+5G6YqWk9l3TZT9ldOT9LLk4TenrQQY+8tWutYQ=
=uO4D
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.